EST · MMXXVI
Home/Insights/Tax/MLRO and compliance officer function: What Recent Enforcement Tells Operators
Compliance, AML & Travel Rule

MLRO and compliance officer function: What Recent Enforcement Tells Operators

Mlro and compliance officer function: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and s

Regulators across every major digital-asset hub have shifted from issuing guidance to issuing fines. The question for any operator is no longer whether a Money Laundering Reporting Officer (MLRO) and a structured compliance function matter – it is what standard those roles are actually held to when examiners arrive. Recent enforcement patterns from the FCA, VARA, MAS and ESMA's network of national competent authorities converge on one conclusion: personal accountability of the designated officer, and the demonstrable independence of the compliance function, are the two fault lines where most cases are made.

This analysis maps what enforcement has actually revealed about expected practice, where operators most commonly fall short, and what a defensible compliance structure looks like for a cross-border digital-asset business today.

What Enforcement Reveals About the MLRO Standard

Regulators do not fail operators for having an imperfect compliance program – they fail them for having a compliance program that exists on paper but not in practice. That distinction drives virtually every enforcement outcome we analyze. The MLRO role, as it now functions under the UK Money Laundering Regulations (MLR) administered by the FCA, under VARA's compliance rulebooks in Dubai, and under the Payment Services Act regime supervised by MAS in Singapore, is a function of operational authority, not organizational title.

What that means in practice is this. An MLRO must have direct board access. The officer must be able to file a Suspicious Activity Report without operational approval from a commercial head. The compliance function must control its own budget line to the extent necessary to carry out its mandate. When examiners review a firm, they trace whether those conditions exist in reality – whether the MLRO had a seat in risk committee, whether SAR decisions were overridden by business-side pressure, whether the transaction monitoring system was calibrated by compliance or by a growth team. Each deviation is a findings point.

In our practice, we see a consistent pattern: the MLRO designation is filed correctly with the regulator at licence application stage, then erodes in authority as the business scales. A new product is launched. The compliance officer is told the risk assessment can follow. Transaction volumes increase. Alert thresholds are nudged upward to reduce ops burden. By the time an examiner calls, the paper structure and the operational reality no longer match.

Cross-Border Structural Risk: Where Does the MLRO Sit?

For a multi-jurisdictional operator, the MLRO function raises a structural question that purely domestic firms do not face: which legal entity owns the compliance obligation, and is the appointed officer genuinely senior in that entity?

A common architecture is a group holding company with subsidiary operating entities licensed in two or more jurisdictions – say, a VARA-licensed exchange in Dubai and an EU-passported CASP entity authorized under MiCA through a national competent authority. Both entities carry independent AML obligations. A single group MLRO located in a third jurisdiction – often the holding-company seat – satisfies neither obligation unless that person is formally appointed as MLRO in each regulated entity and has operational authority there.

ESMA and the relevant national competent authorities under MiCA have been explicit that a CASP must have governance arrangements ensuring the compliance function operates within the licensed entity. The same principle applies under VARA's rulebooks for mainland Dubai operators. MAS, through its Payment Services Act supervisory practice, expects the designated individual to be based – or at minimum sufficiently operationally present – in Singapore. These requirements do not flex easily for a group that wants to centralize compliance in a low-cost location.

The cross-border tension runs further. A firm whose user base spans jurisdictions – including jurisdictions where the firm holds no licence – must assess whether serving those users triggers a local obligation. Regulators in the leading hubs increasingly treat user location as a relevant jurisdictional hook. An MLRO who fails to flag that the firm is onboarding users from a jurisdiction with no licence coverage is, in several recent enforcement narratives, held partly accountable for that structural gap.

Operating without a licensed entity in the jurisdiction where users are located is one of the most frequently cited structural failures in recent digital-asset enforcement actions. For a scoped assessment of your entity structure and compliance allocation, contact OBOLUS at info@oboluslaw.com.

How Regulators Assess KYC Framework Adequacy

A KYC framework (the suite of customer identification, verification, and due diligence controls) is examined not as a policy document but as a live system. Regulators ask whether the controls actually stop what they are designed to stop. The methodology differs by regime, but the analytical questions are consistent across the FCA, VARA, MAS and the MiCA competent authorities.

The first question is risk stratification. Does the firm's customer risk-rating model produce meaningfully differentiated outcomes? A model that places more than ninety percent of customers in low risk tells an examiner one of two things: the business has genuinely low-risk customers, or the model is calibrated to minimize friction rather than reflect actual risk. Examiners probe by sampling enhanced-due-diligence decisions on higher-risk profiles – politically exposed persons, customers from high-risk jurisdictions under the applicable FATF framework, and customers engaged in high-value or unusual transaction patterns.

The second question is refresh. Most firms perform KYC at onboarding. Fewer maintain a systematic trigger-based refresh cycle. Under the applicable VASP provisions in the leading hubs, a stale KYC record on an active customer is a compliance failure even where initial onboarding was correct. Regulators have found violations based on multi-year relationships where material changes in customer profile – business expansion, beneficial ownership changes, adverse media – went unrecorded.

The third question is documentation of decisions. Where a compliance officer or analyst makes an enhanced-due-diligence judgment call – continuing a relationship with a higher-risk customer, approving an unusual transaction structure – that decision must be documented with the reasoning. The absence of documentation is treated as the absence of a decision. In our experience advising firms after regulatory inquiry, the single most damaging posture is a compliance team that made reasonable decisions but wrote nothing down.

The Travel Rule: Operational Reality vs. Regulatory Expectation

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary information alongside a virtual asset transfer – is the compliance obligation where the gap between stated policy and operational reality is widest. Nearly every licensed VASP in a leading hub has a Travel Rule policy. The enforcement record suggests that a significant proportion of those VASPs are not executing it consistently.

The operational challenge is structural. The Travel Rule requires a VASP sending a transfer to transmit the required data to the receiving VASP before or simultaneously with the transfer. Where the receiving VASP is in a jurisdiction without Travel Rule obligations, or where the receiving institution is unhosted (a self-custodied wallet), the sending VASP must apply a risk-based approach to the gap. That risk-based approach must be documented and must result in an actual decision – not a default-to-transmit.

FATF Recommendation 15 and its Interpretive Note apply the Travel Rule to virtual asset transfers at the applicable threshold set by each jurisdiction. In practice, the threshold varies, and the specific figure is set by national implementing legislation. The MLRO owns the policy for managing that gap. Enforcement patterns show that regulators probe Travel Rule compliance by pulling a sample of outbound transactions and testing whether the required data was transmitted, whether the destination was a known VASP or an unhosted address, and whether the decision – including the decision to proceed with an unhosted-wallet transfer – was documented with a risk rationale.

A recurring failure mode is the firm that implemented a Travel Rule solution at licence stage, then failed to maintain it as the volume and complexity of transfers grew. Technology integrations break. VASP directories become stale. New product features – staking, lending, cross-chain bridging – create transfer flows the original Travel Rule solution was not designed to capture. The MLRO who does not conduct periodic testing of Travel Rule execution against actual transaction flows is, in enforcement terms, the MLRO who did not have control.

Transaction Monitoring: Who Owns Calibration?

Transaction monitoring calibration is where the operational independence of the compliance function is tested most directly. The MLRO and the compliance officer must own the parameters of the monitoring system – not the operations team, not the product team, and not the CFO managing alert-handling costs.

Regulators conducting AML audits routinely examine the calibration change log. They look for evidence of who requested threshold changes and why. A change log showing that monitoring thresholds were raised following an operations-team review of alert volumes – with compliance sign-off that reads as rubber-stamp approval rather than independent analysis – is a findings point. The standard the regulator is testing against is whether the compliance function exercised genuine independent judgment.

In our cross-border practice, we regularly advise firms on the governance documentation that should accompany any calibration change: a written rationale prepared by compliance, evidence that the change was tested against known-typology transaction patterns, and board or risk-committee notification where the change is material. That documentation does not guarantee a clean audit. It does demonstrate that the compliance function was performing its function.

The on-chain dimension adds a layer that traditional financial institutions do not face. A VASP's transaction monitoring system must be capable of incorporating blockchain analytics data – transaction hash patterns, cluster-risk outputs from forensic tooling, OFAC-designated address screening. The firm that runs a fiat-era transaction monitoring system on a crypto-native business is running a system that structurally cannot detect the risk typologies it is required to detect. Regulators in the leading hubs have found this structural inadequacy to be an independent violation, separate from any failure to flag a specific transaction.

Personal Accountability of the MLRO: What Enforcement Actually Shows

The shift toward personal accountability of the designated MLRO is the most consequential development in digital-asset AML enforcement in recent years. The FCA under its MLR supervisory regime, VARA under its governance and compliance frameworks, and MAS under the Payment Services Act all carry the formal or practical capacity to take action against an individual compliance officer, not merely the licensed entity.

Personal accountability turns on a straightforward question: did the MLRO know, or should the MLRO have known, that the compliance program was not functioning? That standard does not require evidence of active concealment. Willful blindness – the MLRO who did not look closely because the commercial team did not want findings – is treated as constructive knowledge in most enforcement frameworks.

The practical implication for an MLRO is this: the role requires documented evidence of active oversight, not passive administration. Board papers submitted by the compliance function, written reports of issues identified and escalated, documented disagreements with commercial decisions that implicated compliance obligations – these are the evidentiary record of an MLRO who was performing the role. Their absence, when enforcement arrives, is the absence of a defense.

For operators building or restructuring their compliance function, this means the MLRO appointment is not an HR decision. It is a governance decision that determines the firm's enforcement profile. The individual must have genuine seniority, genuine access, and the institutional standing to push back on commercial decisions that create compliance risk. Firms that appoint a junior compliance analyst to an MLRO role to satisfy a filing requirement are building the enforcement case against themselves.

If your compliance structure is under review – or if a prior regulatory interaction raised questions about the function – a structural assessment now is materially less costly than a remediation program imposed after a formal finding. Write to us at info@oboluslaw.com to scope the review.

An Illustrative Matter: Compliance Gaps in a Cross-Border Exchange

In a recent advisory matter, a digital-asset exchange operating across two licensed entities – one in a Gulf free zone, one in an EU member state – engaged us after receiving a supervisory letter from one of the two regulators questioning the independence of its compliance function. The exchange had a single group MLRO, appointed formally in both entities but operationally based in neither regulated jurisdiction. The MLRO had no reporting line into either local board and had not submitted a compliance report to either regulatory entity in the preceding review period.

We conducted a rapid structural review. The core finding was straightforward: the compliance function's authority existed in the group's organizational documents but had never been operationalized at entity level. The transaction monitoring system was calibrated by the operations team. There was no documented risk-assessment for the unhosted-wallet transfers that represented a material share of the exchange's volume. Travel Rule data was transmitted inconsistently, with no change-log or exception reporting.

We worked with the client to restructure the compliance governance – appointing locally senior compliance officers in each entity, rebuilding the risk-assessment framework, implementing a documented calibration change process, and producing the compliance reporting the regulators expected. The regulatory interaction was resolved in the course of the following quarter without a formal enforcement outcome. The lesson was not new. It was simply expensive to learn late.

Decision Matrix: Which Compliance Structure Fits Which Operator Profile

Not every operator faces the same compliance architecture question. The right structure depends on the entity model, the licence footprint, the product set, and the volume of cross-border transfers. Three profiles recur in our practice.

Profile A is a single-jurisdiction licensed exchange – say, a VARA-licensed operator in Dubai serving a predominantly GCC user base. This operator needs a locally senior MLRO with genuine board access, a transaction monitoring system calibrated to the specific risk typologies of the product set, and a documented Travel Rule process for outbound transfers. The complexity is manageable. The risk is complacency – the firm that passes its first licence review and treats compliance as a solved problem.

Profile B is a group with multiple licensed entities in different regulatory regimes – a MiCA-passported CASP and a Payment Services Act licensee in Singapore, for example. This operator needs an MLRO designated in each regulated entity, an overarching group compliance function that sets policy standards, and clear documented governance showing how the group policy is implemented locally. The risk is structural mismatch – a group compliance function that writes policy but has no visibility into execution at entity level.

Profile C is a firm that holds one licence but serves users in multiple jurisdictions on the basis that the licence covers the activity. This operator faces a different risk profile: the licensing question and the compliance question are entangled. If the licence does not cover the jurisdictions where users are located, the MLRO's KYC framework may be technically sound for the licensed population while the operator is simultaneously in violation of local requirements in the jurisdictions it is actually serving. The compliance function cannot solve a licensing problem. But a compliance officer who identifies the exposure and escalates it has documented an important defensive record.

Addressing the Common Assumption: One Offshore Licence Covers Global Operations

A persistent operating assumption in the digital-asset sector is that a single offshore licence – a BVI VASP registration, a Cayman Islands CIMA filing, or an equivalent – provides sufficient regulatory cover to serve clients globally. Enforcement and regulatory guidance consistently show otherwise. The licence is a necessary condition for operating in the issuing jurisdiction. It is not a substitute for a licence, registration, or compliance posture in the jurisdiction where the user or counterparty is actually located.

This matters for the MLRO function in a specific way. The KYC and AML obligations that apply to a given customer interaction are set by the regime that governs the relationship – which may be the user's jurisdiction, not the firm's. FATF standards, applied through national legislation, create AML obligations that are triggered by the location of the activity and the parties, not solely by the location of the licensed entity. An MLRO who designs a compliance program solely around the requirements of the offshore licensing jurisdiction, without assessing the applicable obligations in the jurisdictions where users are located, has designed an incomplete program.

The FCA has been explicit on this point for UK-nexus transactions. MAS expects equivalent analysis for Singapore-user exposures. ESMA's guidance under MiCA requires a CASP to assess the jurisdictional scope of its activities as part of its authorization application. The offshore-licence-sufficiency assumption is not a legal position that survives regulatory scrutiny in the leading hubs.

We map the licence stack across operating, custody and payment layers before clients commit to a structure. That mapping is not an overhead – it is the document that allows the MLRO to design a compliance program that actually reflects the firm's regulatory perimeter.

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a virtual asset service provider to collect and transmit originator and beneficiary information alongside a virtual asset transfer. The specific data fields and the applicable threshold vary by jurisdiction and are set by national implementing legislation. A sending VASP must also apply a documented risk-based approach where the receiving party is an unhosted wallet or is located in a jurisdiction without equivalent Travel Rule obligations.

Who must act as MLRO for a crypto firm?

The MLRO must be a sufficiently senior individual with genuine operational authority in the licensed entity – not merely a compliance analyst holding a title. Most leading regimes require the MLRO to have direct board access, the ability to file Suspicious Activity Reports without commercial override, and adequate resources to discharge the function. For multi-entity groups, a separate MLRO designation is typically required in each regulated entity rather than a single group appointment.

How do regulators audit crypto AML programs?

Regulators conducting AML audits typically examine the risk assessment, KYC records, transaction monitoring calibration and change logs, Travel Rule execution, SAR filing records, and the compliance function's governance documentation. They probe whether the program reflects actual operations – not just policy – by sampling transaction decisions, reviewing monitoring alerts and dispositions, and testing whether the MLRO had genuine decision-making authority. A clean audit requires demonstrable operational independence of the compliance function, not only written policies.

About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance frameworks that sit around them. We map the licence stack across operating, custody and payment layers before clients commit to a structure. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. Digital assets are the whole of our practice. To discuss your compliance structure, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Lydia Brennan, Tax & Structuring Analyst – specializing in cross-border AML compliance architecture and the interaction between tax structuring and regulatory obligations for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours